The BlackFile extortion group collected roughly $10.69 million in Bitcoin between January and May 2026 while cycling through multiple brand identities to disguise its scale, according to an analysis published by Google Threat Intelligence Group. Despite announcing the retirement of its BlackFile brand in 2026, the gang has since operated under the names Redact, Pink, Helix, and Falcon, all while maintaining identical infrastructure and phishing tactics. The group targets enterprise employees through voice phishing calls that impersonate IT helpdesk staff, then harvests credentials and multi-factor authentication tokens to raid cloud environments.
Google's analysis traced 18 BlackFile Bitcoin wallet addresses that received a total of 141.65 BTC between January 7 and May 12, representing approximately $10.69 million at the time the funds changed hands. The group's targeting strategy shifted dramatically across the four-month span from April to July 2026. Between April and May, the operation focused on large companies in manufacturing, real estate, healthcare, and insurance. In June, it pivoted toward technology, transportation, and hospitality businesses, before narrowing its sights in July exclusively to high-value targets in finance and law, including private equity firms, law offices, and credit rating agencies. Google was able to link all five extortion brands because the gang reused generic root domains such as passkeyhelpdesk[.]com and passkeydeploy[.]com across multiple victims, sometimes deploying the same domain simultaneously against two entirely separate targets claimed by different brand names.
Google wrote that the widespread use of matching phishing templates across multiple data leak site brands "suggests they rely on shared underlying infrastructure." The Redact operators published a statement on June 27 explaining their rebrand from BlackFile, claiming the original brand had been compromised and hijacked by an expelled affiliate. According to the group's public communications, a rogue affiliate had operated an unauthorized, copycat data leak site and ran unsanctioned extortion campaigns using BlackFile's name with unconnected Tox identities, and was also blamed for orchestrating the supposed shutdown of the BlackFile brand in May 2026. Google's researchers said the gang's public statements cited an affiliate breakaway as the justification for the initial rebrand, but overlaps in phishing templates, victim profiles, and shared infrastructure pathways indicate that linked actors have since exploited the Pink, Helix, and Falcon extortion brands to profit from their operations.
The gang's playbook has remained consistent regardless of which name it operates under. Attackers phone employees on their personal devices, posing as IT helpdesk personnel and claiming an urgent mandate to enable FIDO2 passkeys or update multi-factor authentication enrollment. Victims are directed to spoofed login portals where Adversary-in-the-Middle infrastructure captures credentials and MFA tokens in real time. Once session persistence is achieved, automated scripts exfiltrate data from enterprise cloud platforms, including Microsoft 365 and Okta. New techniques observed by Google include spoofing legitimate helpdesk phone numbers and using compromised email accounts to reset passwords for enterprise applications, then deleting security notifications and alert emails to dodge detection and maintain ongoing access. Google's report recommends enforcing phishing-resistant authenticators, integrating single sign-on, enforcing session controls to reduce session length, and restricting authentication to trusted network sources. Because the scam often involves vishing calls that target personal devices, Google said firms should ensure that authentication comes from a corporate-managed endpoint with mobile device management and endpoint detection and response.
Operating multiple extortion brands simultaneously allows the group to compartmentalize its activities and obscure the true volume of breaches it conducts, making it harder for law enforcement and security researchers to track its full footprint. By fragmenting its public identity, the gang can also isolate any fallout from failed negotiations or public exposure under one brand without contaminating its other operations. The shift toward high-value financial and legal targets in July suggests the group is refining its victim selection to maximize ransom payouts while minimizing the number of intrusions required to sustain revenue. For enterprise security teams, the lesson is clear: voice phishing remains a potent vector because it bypasses technical controls by manipulating the human element, and multi-factor authentication alone won't stop attackers who can intercept tokens in real time through adversary-in-the-middle infrastructure.

